United States - Vermont - AI in Insurance (DFR Bulletin 229)
Vermont DFR Bulletin No. 229 — The Use of Artificial Intelligence Systems in Insurance
United States
RAI-US-VT-V8AIXXX-2024Bulletin 229
The Vermont DFR's Bulletin No. 229 guides insurers on AI use, adopting the NAIC Model and applying existing state laws to ensure fairness, transparency, and consumer protection.
Summary
Read full text ↗Plain English
Overview
The regulatory landscape for Artificial Intelligence (AI) in the insurance sector in Vermont is primarily shaped by the Vermont Department of Financial Regulation (DFR) through its comprehensive guidance rather than a standalone legislative act specifically titled 'Vermont Act 89 - AI in Insurance.' On March 12, 2024, the DFR issued Bulletin No. 229, officially titled 'The Use of Artificial Intelligence Systems in Insurance.' This pivotal document outlines the Department's expectations for all insurers holding certificates of authority to conduct business within the state concerning their engagement with advanced analytical and computational technologies, including AI systems. The bulletin explicitly states that all decisions and actions impacting consumers, whether made or supported by AI, must adhere strictly to existing applicable insurance laws and regulations. This includes, but is not limited to, statutes addressing unfair trade practices and prohibiting unfair discrimination, ensuring that the integration of AI into insurance operations does not compromise consumer protections or market integrity.
A significant aspect of DFR Bulletin No. 229 is its principal adoption of the National Association of Insurance Commissioners (NAIC) Model on the Use of Artificial Intelligence Systems by Insurers. This alignment underscores Vermont's commitment to harmonizing its regulatory approach with national best practices, fostering a consistent and robust framework for AI governance in the insurance industry. The bulletin acknowledges the transformative potential of AI to drive innovation, enhance consumer services, streamline processes, and improve accuracy across various stages of the insurance lifecycle, from product development and underwriting to claims management and fraud detection. However, it equally highlights the unique risks associated with AI, such as the potential for inaccuracy, unfair discrimination, data vulnerability, and a lack of transparency and explainability. The DFR's guidance is designed to balance these innovative opportunities with the imperative to safeguard consumer interests and maintain a fair, secure, and robust insurance system.
Definitions
DFR Bulletin No. 229 provides crucial definitions to establish a common understanding of terms within the context of AI in insurance. While the bulletin itself may draw upon or refer to the NAIC Model for comprehensive definitions, its core focus is on 'Artificial Intelligence (AI) Systems.' These systems are generally understood to encompass advanced analytical and computational technologies that enable machines to simulate human intelligence, including learning, problem-solving, and decision-making capabilities. In the insurance context, AI Systems are applied across various functions, such as underwriting, pricing, claims processing, fraud detection, and customer service. The bulletin clarifies that the regulatory expectations apply to any such system that influences or makes decisions affecting consumers.
Furthermore, the bulletin implicitly defines the scope of 'insurers' as all entities holding certificates of authority to do business in Vermont, thereby ensuring broad applicability of the guidance. It also introduces the concept of a 'Third Party' as an organization other than the insurer that provides services, data, or other resources related to AI. This distinction is critical for delineating responsibilities and ensuring that insurers remain accountable for AI systems, even when developed or managed by external vendors. The DFR's emphasis on these definitions helps to clarify the regulated entities and technologies, ensuring that the principles of fairness, accountability, and transparency are applied consistently across the insurance ecosystem, regardless of whether AI capabilities are developed in-house or outsourced.
Governance and Institutional Framework
The primary institutional framework for overseeing the use of AI in insurance within Vermont rests with the Vermont Department of Financial Regulation (DFR). The DFR is responsible for issuing regulatory guidance, monitoring compliance, and enforcing existing insurance laws as they apply to AI systems. The bulletin explicitly states that the DFR's position is that existing state insurance laws and rules already apply to insurer use of AI, thereby integrating AI governance into the established regulatory structure. This approach leverages the DFR's existing authority and expertise in regulating financial markets and institutions, including the insurance sector, to address the emerging challenges posed by AI. The Department's mission to promote financial health, stability, and integrity, and to protect the public through consistent enforcement, extends directly to the oversight of AI applications in insurance.
Internally, insurers are mandated to establish robust governance structures for their AI systems. The DFR expects insurance companies to develop and maintain comprehensive written policies and procedures that govern the entire lifecycle of AI in their operations, from development and acquisition to implementation and ongoing monitoring. These internal governance mechanisms are crucial for providing clear guidance on the design, deployment, and oversight of AI systems, ensuring they align with regulatory requirements and ethical principles. The DFR's framework places significant responsibility on insurers to proactively manage the risks associated with AI, emphasizing accountability at the organizational level. This includes establishing clear lines of responsibility for AI system development, deployment, and performance, as well as ensuring that personnel involved in these processes are adequately trained and aware of their compliance obligations.
Key Focus Areas
DFR Bulletin No. 229 highlights several key focus areas to ensure the responsible and ethical deployment of AI in the insurance sector. Paramount among these is consumer protection, which underpins all regulatory expectations. The DFR reiterates that decisions or actions affecting consumers, whether made or supported by AI, must comply with all applicable insurance laws, especially those prohibiting unfair trade practices and unfair discrimination. This ensures that AI systems do not lead to adverse outcomes for policyholders or applicants, such as denial of coverage, increased premiums, or biased claims settlements, without legitimate, non-discriminatory grounds. The bulletin explicitly warns against the potential for AI to introduce or exacerbate inaccuracies, unfair bias, and data vulnerability, making these critical points of attention for insurers.
Another central theme is transparency and explainability. While the bulletin doesn't mandate specific technical explainability methods, it emphasizes that insurers must be able to justify AI-driven decisions and demonstrate their compliance with legal standards. This implies a need for systems that are auditable and understandable, allowing regulators and consumers to comprehend how AI models arrive at their conclusions. Coupled with this is accountability, requiring insurers to take full responsibility for the outcomes of AI systems, even when third-party vendors are involved. Insurers must implement robust risk management controls to identify, assess, and mitigate potential risks associated with AI, including algorithmic bias, data security breaches, and model drift. These controls are expected to be integrated into an insurer's overall enterprise risk management framework, ensuring a holistic approach to managing AI-related challenges. The bulletin's focus areas collectively aim to foster an environment where AI innovation can thrive responsibly, without undermining the fundamental rights and protections of consumers.
Implementation Framework
The implementation framework articulated in DFR Bulletin No. 229 places a strong emphasis on proactive measures by insurers to ensure compliance and responsible AI use. Insurers are expected to integrate the bulletin's principles and the NAIC Model's guidelines into their existing operational and compliance structures. A foundational requirement is the development and maintenance of comprehensiv e written policies and procedures specifically governing the use of AI in their operations. These documents should provide clear guidance on the entire lifecycle of AI systems, including their design, development, acquisition, implementation, monitoring, and ongoing evaluation. This level of documentation is critical for demonstrating adherence to regulatory expectations and for fostering a culture of responsible AI within the organization.
Furthermore, the bulletin mandates the establishment of robust risk management controls designed to identify, assess, and manage the various potential risks associated with AI systems. These risks encompass, but are not limited to, algorithmic bias, data privacy breaches, model inaccuracy, lack of transparency, and potential for unfair discrimination. Insurers are expected to implement mechanisms to continuously monitor AI system performance, detect anomalies, and address any issues promptly. This includes conducting regular impact assessments to evaluate the fairness and accuracy of AI models, particularly those used in critical decision-making processes affecting consumers. The DFR's framework ensures that insurers are not only aware of the risks but are also equipped with the necessary tools and processes to mitigate them effectively, thereby upholding the integrity of the insurance market and protecting consumer interests.
Monitoring and Evaluation
The Vermont Department of Financial Regulation (DFR) maintains an active role in the monitoring and evaluation of insurers' adherence to the guidelines set forth in Bulletin No. 229 regarding the use of AI systems. The bulletin explicitly states that the DFR may request specific information and documentation during the course of an investigation or examination to determine compliance. This oversight mechanism allows the Department to assess whether insurers have effectively implemented the required policies, procedures, and risk management controls for their AI systems. The scope of such requests can be broad, covering aspects from the initial design and training data of an AI model to its ongoing performance, impact assessments, and the rationale behind AI-driven decisions affecting consumers.
Insurers are therefore expected to maintain thorough records and be prepared to demonstrate, upon request, how their AI systems comply with existing insurance laws, particularly those pertaining to unfair trade practices and unfair discrimination. This includes evidence of regular testing for bias, documentation of model validation processes, and records of any corrective actions taken in response to identified issues. The DFR's ability to conduct these examinations serves as a critical enforcement tool, ensuring that the principles of fairness, transparency, and accountability are not merely aspirational but are actively integrated into insurers' AI practices. The ongoing monitoring and evaluation framework underscores the DFR's commitment to adapting its regulatory oversight to the evolving technological landscape, ensuring that innovation in AI within the insurance sector proceeds responsibly and with robust consumer safeguards.
Penalties, Liability, and Appeals
DFR Bulletin No. 229 clarifies that the use of Artificial Intelligence (AI) systems by insurers remains subject to the full force of existing Vermont insurance laws and regulations. Consequently, any violations arising from the deployment or operation of AI systems that lead to unfair trade practices or unfair discrimination will incur penalties and liabilities as prescribed by these established statutes. Specifically, Vermont's insurance trade practices laws, codified in 8 V.S.A. §§ 4721-4724 and 4727, define and prohibit various unfair methods of competition and unfair or deceptive acts in the business of insurance. Insurers found to be in violation through their AI systems could face administrative sanctions, fines, and other enforcement actions typically applied under these laws. The bulletin reinforces that the use of AI does not exempt insurers from their fundamental legal obligations to consumers.
The bulletin implies that the existing mechanisms for consumer redress and appeals within the Vermont insurance regulatory framework would also apply to issues stemming from AI-driven decisions. If an AI system leads to an adverse decision (e.g., denial of coverage, increased premium, or unfavorable claims outcome) that a consumer believes is unfair, discriminatory, or in violation of state law, they would likely have the right to appeal that decision through the insurer's internal processes and, subsequently, to the DFR. The DFR's role includes investigating consumer complaints and enforcing compliance. The explicit linkage of AI use to existing unfair trade practices and discrimination laws means that the legal liability for harmful outcomes generated by AI systems ultimately rests with the insurer, regardless of whether the AI was developed in-house or by a third party. This ensures a clear chain of accountability and provides a pathway for consumers to seek remedies for any damages or unfair treatment resulting from AI in insurance.
Relationship to Other Instruments
DFR Bulletin No. 229 establishes a clear relationship between the emerging use of Artificial Intelligence (AI) in insurance and Vermont's existing legal and regulatory framework. Critically, the bulletin explicitly states that decisions or actions impacting consumers that are made or supported by AI Systems must comply with all applicable insurance laws and regulations already in force. This includes, most notably, Vermont's insurance trade practices laws, specifically Title 8 V.S.A. §§ 4721-4724 and 4727. These statutes define and prohibit unfair methods of competition and unfair or deceptive acts and practices in the business of insurance. By directly linking AI use to these established laws, the DFR ensures that the principles of fairness, non-discrimination, and transparency are upheld, regardless of the technological tools employed by insurers.
Furthermore, the bulletin references Vermont's claims settlement related laws and regulations, including 8 V.S.A § 4724(9) and Regulation 79-2. This connection underscores that AI systems used in claims management must also adhere to standards for fair and prompt claims handling, preventing any algorithmic biases or inefficiencies from leading to unfair settlement practices. A cornerstone of the bulletin's approach is its principal adoption of the National Association of Insurance Commissioners (NAIC) Model on the Use of Artificial Intelligence Systems by Insurers. This adoption signifies Vermont's commitment to aligning its regulatory expectations with a nationally recognized framework, promoting consistency across state lines and providing insurers with a clear, principles-based guide for responsible AI deployment. This integration with the NAIC Model helps ensure that Vermont's regulatory posture on AI in insurance is both robust and harmonized with broader industry standards.
International Alignment
Given that DFR Bulletin No. 229 is a regulatory instrument issued by a state-level department in the United States, its primary focus and direct legal applicability are within the state of Vermont. Therefore, it does not directly seek or establish explicit alignment with international AI regulatory instruments or frameworks. The bulletin's scope is inherently domestic, addressing the specific legal and market conditions within Vermont's insurance sector. However, the indirect influence of broader international discussions on AI ethics and governance can be observed through its foundational principles. The emphasis on fairness, accountability, transparency, and consumer protection within the bulletin reflects universal concerns that are also central to many international AI policy discussions and recommendations from bodies like the OECD, UNESCO, and the European Union.
Moreover, the bulletin's principal adoption of the National Association of Insurance Commissioners (NAIC) Model on the Use of Artificial Intelligence Systems by Insurers provides a degree of national alignment within the U.S. insurance regulatory landscape. While the NAIC is a U.S.-based organization, its model laws and bulletins often draw upon global best practices and evolving standards in risk management and consumer protection. Thus, while not directly an international alignment, the DFR's approach through the NAIC Model contributes to a more harmonized and principles-based regulatory environment that can indirectly resonate with international efforts to govern AI responsibly. The bulletin's focus remains on ensuring that AI use within Vermont's insurance market adheres to established domestic legal and ethical standards, prioritizing the protection of Vermont consumers.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Issuance of DFR Bulletin No. 229 | 2024-03-12 | The bulletin was officially issued by the Vermont Department of Financial Regulation. |
| Effective Date of Bulletin | 2024-03-12 | The guidance and expectations outlined in the bulletin took effect upon its issuance. |
| Insurers' Compliance Expectation | Ongoing from 2024-03-12 | Insurers are expected to immediately and continuously comply with all applicable insurance laws and regulations when using AI systems, and to develop and maintain necessary policies and controls. |
| DFR Monitoring and Examination | Ongoing from 2024-03-12 | The DFR may request documentation and conduct examinations to assess compliance at any time. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Compliance with Existing Laws | Ensure all AI-driven decisions and actions comply with Vermont's unfair trade practices (8 V.S.A. §§ 4721-4724, 4727) and unfair discrimination laws. |
| Written Policies & Procedures | Develop and maintain comprehensive written policies and procedures governing the development, acquisition, implementation, and monitoring of all AI systems in use. |
| Risk Management Controls | Implement robust risk management controls to identify, assess, and mitigate potential risks associated with AI, including inaccuracy, bias, and data vulnerability. |
| Transparency & Explainability | Be prepared to explain AI-driven decisions and demonstrate how they adhere to legal and ethical standards, especially for consumer-impacting outcomes. |
| Data Governance | Ensure appropriate data governance measures are in place for training data sets to prevent bias and ensure data quality and security. |
| Accountability Framework | Establish clear lines of accountability for the design, deployment, and performance of AI systems, including those provided by third parties. |
| Documentation & Record-Keeping | Maintain thorough documentation of AI system design, testing, impact assessments, and ongoing performance for DFR review. |
| Continuous Monitoring | Implement processes for continuous monitoring of AI systems to detect and address issues such as model drift or emerging biases. |
| Training & Awareness | Ensure personnel involved in AI development and deployment are trained on compliance obligations and ethical AI principles. |
Sources and References
| Source | Type |
|---|---|
| Insurance Bulletin No. 229 The Use of Artificial Intelligence Systems in Insurance | official |
| DFR Issues Comprehensive Bulletin on Use of AI Systems in the Business of Insurance | government |
| Industry - Vermont Department of Financial Regulation | government |
Vermont's Department of Financial Regulation (DFR) has issued guidance for all insurers operating in the state, clarifying how existing laws apply to their use of Artificial Intelligence (AI) systems to ensure fairness, transparency, and consumer protection. This guidance, DFR Bulletin No. 229, took effect immediately on March 12, 2024, and applies to all insurance companies authorized to do business in Vermont, covering any AI system that influences or makes decisions affecting consumers.
The core message is that AI does not create a loophole for existing regulations. Insurers must ensure that all AI-driven decisions and actions comply with Vermont's insurance laws, especially those prohibiting unfair trade practices and discrimination. Key obligations include: - Developing and maintaining comprehensive written policies and procedures for the entire lifecycle of AI systems, from development to monitoring. - Implementing robust risk management controls to identify, assess, and mitigate potential AI-related risks like algorithmic bias, data inaccuracy, and security vulnerabilities. - Being able to explain AI-driven decisions and demonstrate how they meet legal and ethical standards, particularly for outcomes impacting consumers.
The DFR has adopted the National Association of Insurance Commissioners (NAIC) Model on AI use, aligning Vermont with national best practices. The Department began continuous monitoring and examination of AI use from March 12, 2024, and can request documentation at any time to assess compliance.
Failure to comply means insurers face the same administrative sanctions, fines, and enforcement actions as any other violation of Vermont's insurance laws, such as those against unfair trade practices. A crucial practical pitfall for insurers is that they remain fully accountable for the outcomes of AI systems, even if those systems are developed or managed by third-party vendors. This means the legal liability for any harmful or discriminatory results generated by AI ultimately rests with the insurer.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under United States - Vermont - AI in Insurance (DFR Bulletin 229). Not legal advice — verify against the official text before relying on it.
- #1Critical8 V.S.A. §§ 4721-4724, 4727⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“all decisions and actions impacting consumers... must adhere strictly to existing applicable insurance laws and regulations.”
- #2Critical8 V.S.A § 4724(9) and Regulation 79-2⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in claims management in Vermont
“AI systems used in claims management must also adhere to standards for fair and prompt claims handling.”
- #3Critical⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“the DFR may request specific information and documentation during the course of an investigation or examination.”
- #4Critical⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“insurers are mandated to establish robust governance structures for their AI systems.”
- #5Critical⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“insurers remain accountable for AI systems, even when developed or managed by external vendors.”
- #6Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“develop and maintain comprehensive written policies and procedures that govern the entire lifecycle of AI.”
- #7Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“implement robust risk management controls to identify, assess, and mitigate potential risks associated with AI.”
- #8Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“establishing clear lines of responsibility for AI system development, deployment, and performance.”
- #9Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“insurers must be able to justify AI-driven decisions and demonstrate their compliance with legal standards.”
- #10Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“implement mechanisms to continuously monitor AI system performance, detect anomalies, and address any issues promptly.”
- #11Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“conducting regular impact assessments to evaluate the fairness and accuracy of AI models.”
- #12Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“maintain thorough records and be prepared to demonstrate... how their AI systems comply.”
- #13Important⏰ Ongoing from 2024-03-12
Applies to: Insurers using AI systems in Vermont
“personnel involved in these processes are adequately trained and aware of their compliance obligations.”
Related Regulations
An act relating to creating oversight and liability standards for developers and deployers of inherently dangerous artificial intelligence systems
United States91% similar
Connecticut Artificial Intelligence Responsibility and Transparency Act
Connecticut, United States90% similar
Colorado SB 21-169 - AI in Insurance Underwriting
United States89% similar
Connecticut AI Impact Assessment Requirements
United States89% similar
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers
United States89% similar
© Regulations.AI — created on 13-Jun-2026 using Gemini 2.5 Flash